From owner-freebsd-stable@FreeBSD.ORG Wed Jul 16 21:48:49 2008 Return-Path: Delivered-To: stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 78DF2106564A for ; Wed, 16 Jul 2008 21:48:49 +0000 (UTC) (envelope-from spork@bway.net) Received: from xena.bway.net (xena.bway.net [216.220.96.26]) by mx1.freebsd.org (Postfix) with ESMTP id 1341B8FC12 for ; Wed, 16 Jul 2008 21:48:48 +0000 (UTC) (envelope-from spork@bway.net) Received: (qmail 38997 invoked by uid 0); 16 Jul 2008 21:22:08 -0000 Received: from unknown (HELO office-dhcp-35.bway.net) (spork@216.220.107.35) by smtp.bway.net with (DHE-RSA-AES256-SHA encrypted) SMTP; 16 Jul 2008 21:22:08 -0000 Date: Wed, 16 Jul 2008 17:22:07 -0400 (EDT) From: Charles Sprickman X-X-Sender: spork@hotlap.local To: Jeremy Chadwick In-Reply-To: <20080716205705.GA25198@eos.sc1.parodius.com> Message-ID: References: <20080716162042.GA27666@svzserv.kemerovo.su> <20080716205705.GA25198@eos.sc1.parodius.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Cc: stable@freebsd.org, Eugene Grosbein Subject: Re: named.conf: query-source address X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Jul 2008 21:48:49 -0000 On Wed, 16 Jul 2008, Jeremy Chadwick wrote: > On Thu, Jul 17, 2008 at 12:20:42AM +0800, Eugene Grosbein wrote: >> I fully understand and second efforts on educating people >> how to configure BIND to be stong to attacks and keep them from using >> "query-source address" with "port" option but how about >> binding named to particular IP address when host has many of them? > > We do such on our authoritative nameservers. The options we use: Same here... > listen-on { 127.0.0.1; 72.20.106.4; }; > query-source address 72.20.106.4; > transfer-source 72.20.106.4; > notify-source 72.20.106.4; But just that portion. It works, and it passes the test with a std. dev of 19K or so on the port "randomness". Charles > interface-interval 0; > use-alt-transfer-source no; > > -- > | Jeremy Chadwick jdc at parodius.com | > | Parodius Networking http://www.parodius.com/ | > | UNIX Systems Administrator Mountain View, CA, USA | > | Making life hard for others since 1977. PGP: 4BD6C0CB | > > _______________________________________________ > freebsd-stable@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-stable > To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org" >